A browser extension called Twitch Enhanced Viewer | JeetBot has been found sending Twitch OAuth session tokens belonging to nearly 31,000 users to proxy servers controlled by the operator of a commercial bot service. Security researchers at Socket discovered that the extension was available through both Chrome and Firefox and was promoted as a tool for an ad-free Twitch experience, region-unlocked content and other viewing features. The extension had around 30,000 Chrome users and 552 Firefox users when the issue was reported, putting the total exposure at roughly 30,552 users.
The main concern is the way the extension handled users’ authentication tokens while playing Twitch streams. Instead of sending video playlist requests directly to Twitch, the extension redirected those requests through proxy servers operated by the JeetBot service and attached the user’s OAuth token to the request as an auth parameter. Researchers said the token was an account-scoped credential rather than a limited playback token, meaning it could potentially be used to act as the authenticated Twitch user. Such a token can provide access to actions including reading and sending whispers, posting in chat and spending channel points without requiring the user’s password or second-factor code.
Researchers also found that earlier versions of the extension used an even more direct method of sending the tokens. Versions from the v4.x series, including a January 2026 release, reportedly sent the token through a dedicated set-token endpoint hosted on infrastructure controlled by the operator, with additional backups on Deno-hosted domains. In newer versions, the token was forwarded through the proxy when Twitch video playlists were requested, while a specific list of ten channels was excluded from this process. The operator explained that the exception was created as a playback workaround for users who received Twitch’s proxy or unblocker error when watching certain channels from outside Russia or through a VPN.
The infrastructure involved has been linked to JeetBot, a commercial service offering bot functionality for Twitch, Kick and VK Live. JeetBot advertises features such as message speech synthesis, automatic translation and other tools for streamers, and claims to have more than 26,000 active streamers and one billion processed messages. The service’s website identifies a Cyprus-based developer, Aleksandr Popov, who has described JeetBot as a personal project. The extension developer has rejected the description of the software as malicious, saying the token forwarding was intended to support playback features and was not designed for unauthorized activity, while acknowledging that the previous implementation created a security risk.
After researchers raised the issue, the developer changed the Firefox extension so that Twitch OAuth tokens are no longer sent through the operator’s proxy servers. An alert on the JeetBot documentation says Firefox version 85.8.7 fixes the problem and advises users to update to that version or later, while an equivalent Chrome update had been submitted and was awaiting review by the Chrome Web Store. The developer also recommended temporarily disabling the extension if the updated version was unavailable. However, simply disabling or updating the extension does not revoke tokens that may already have been transmitted, so users potentially affected by the earlier versions should take additional account-security steps.
The incident is another reminder that browser extensions can have access to highly sensitive information even when they appear to provide harmless or useful features. Socket said the exposed Twitch OAuth tokens function as bearer credentials, meaning possession of the token can allow actions on an account without the normal password and two-factor authentication process. Users who installed Twitch Enhanced Viewer | JeetBot should remove or disable the extension, review their Twitch sessions and account access, and reauthenticate where necessary. The case also shows why users should carefully review extension permissions and updates, because being available through an official browser store does not by itself guarantee that every version of an extension is safe.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news